Valid Accounts, Technique T1078 - Enterprise | MITRE ATT&CK®
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop.[1] Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence. In some cases, adversaries may abuse inactive accounts: for example, those belonging to individuals who are no longer part of an organization. Using these accounts may allow the adversary to evade detection, as the original account user will not be p
Valid Accounts, Technique T1078 - Enterprise | MITRE ATT&CK® ATT&CKcon 7.0 is coming October 27-28, 2026. Learn more about ATT&CKcon 7.0 . Home Techniques Enterprise Valid Accounts Valid Accounts Sub-techniques (4) ID Name T1078.001 Default Accounts T1078.002 Domain Accounts T1078.003 Local Accounts T1078.004 Cloud Accounts Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the
Explore this link on the map →related reading
- Initial Access, Tactic TA0001 - Enterprise | MITRE ATT&CK®attack.mitre.org
- Account Manipulation, Technique T1098 - Enterprise | MITRE ATT&CK®attack.mitre.org
- Anomalies detected by the Microsoft Sentinel machine learning engine | Microsoft Learnlearn.microsoft.com
- Persistence, Tactic TA0003 - Enterprise | MITRE ATT&CK®attack.mitre.org
- Remote Services, Technique T1021 - Enterprise | MITRE ATT&CK®attack.mitre.org
- PerfectData Software Abuse and Account Takeover Risksdarktrace.com
- Shifting detection left for more effective threat detectionpushsecurity.com
- Common Oauth Apps Used in Business Email Compromise - Syne's Cyber Cornercybercorner.tech
- External Remote Services, Technique T1133 - Enterprise | MITRE ATT&CK®attack.mitre.org
- Exposing and shutting down an inbox heist in actionredcanary.com
- When MFA isn’t an option: The legacy of ROPC | Red Canaryredcanary.com
- Email Compromise To Mass Phishing Campaigndarktrace.com